Font size
WorksheetsNSE7 - Test - No. 1
Total questions: 109
Worksheet time: 3hrs 44mins
Multiple IPsec VPNs are formed between two hub-and-spokes groups, and site-to-site between Hub 1 and Hub 2. The administrator configured ADVPN on the dual regions topology. Which two statements are correct if a user in Toronto sends traffic to London? (Choose two.)
Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.
The first packets from Toronto to London are routed through Hub 1 then to Hub 2.
London generates an IKE information message that contains the Toronto public IP address.
Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN
Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
FortiGate is not performing traffic shaping as expected, based on the policies shown in the exhibits.
To correct this traffic shaping issue on FortiGate, what configuration change must be made on which policy?
The URL category must be specified on the traffic shaping policy.
The shaper mode must be applied per-IP shaper on the traffic shaping policy.
The web filter profile must be enabled on the firewall policy.
The application control profile must be enabled on the firewall policy
Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?
The 10 Mbps bandwidth is shared equally among the IP addresses.
Each IP is guaranteed a minimum 10 Mbps of bandwidth.
FortiGate allocates each IP address a maximum 10 Mbps of bandwidth.
A single user uses the allocated bandwidth divided by total number of users.
Which three parameters are available to configure SD-WAN rules? (Choose three.)
(Application signatures)
(Internet service database - ISDB - address object)
(Source and destination IP address)
(Type of physical link connection)
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?
diagnose sys virtual-wan-link health-check
Which diagnostic command can you use to show the SD-WAN rules interface information and state?
Exhibit A shows the performance SLA exhibit B shows the SD-WAN diagnostics output.
Based on the exhibits, which statement is correct?
Port1 became dead because no traffic was offload through the egress of port1.
SD-WAN member interfaces are affected by the SLA state of the inactive interface.
Both SD-WAN member interfaces have used separate SLA targets.
The SLA state of port1 is dead after five unanswered requests by the SLA servers.
Which statement is correct about the SD-WAN and ADVPN?
Spoke support dynamic VPN as a static interface.
Dynamic VPN is not supported as an SD-WAN interface.
ADVPN interface can be a member of SD-WAN interface.
Hub FortiGate is limited to use ADVPN as SD-WAN member interface.
Which two reasons make forward error correction (FEC) ideal to enable in a phase one VPN interface? (Choose two.)
FEC is useful to increase speed at which traffic is routed through IPsec tunnels.
FEC transmits the original payload in full to recover the error in transmission.
FEC transmits additional packets as redundant data to the remote device.
FEC improves reliability, which overcomes adverse WAN conditions such as noisy links.
FEC reduces the stress on the remote device jitter buffer to reconstruct packet loss.
Exhibit A shows the source NAT global setting and exhibit B shows the routing table on FortiGate. Based on the exhibits, which two statements about increasing the port2 interface priority to 20 are true? (Choose two.)
All the existing sessions that do not use SNAT will be flushed and routed through port1.
All the existing sessions will continue to use port2, and new sessions will use port1.
All the existing sessions using SNAT will be flushed and routed through port1.
All the existing sessions will be blocked from using port1 and port2.
Which components make up the secure SD-WAN solution?
Which two statements about the status of the VPN tunnel are true? (Choose two.)
There are separate virtual interfaces for each dial-up client.
VPN static routes are prevented from populating the FortiGate routing table.
FortiGate created a single IPsec virtual interface that is shared by all clients.
100.64.3.1 is one of the remote IP address that comes through index interface 1.
Exhibit A shows the SD-WAN rules and exhibit B shows the traffic logs. The SD-WAN traffic logs reflect how FortiGate processed traffic. Which two statements about how the configured SD-WAN rules are processing traffic are true? (Choose two.)
The implicit rule overrides all other rules because parameters widely cover sources and destinations.
SD-WAN rules are evaluated in the same way as firewall policies: from top to bottom.
The All_Access_Rules rule load balances Vimeo application traffic among SD-WAN member interfaces.
The initial session of an application goes through a learning phase in order to apply the correct rule
What are the two minimum configuration requirements for an outgoing interface to be selected once the SD-WAN logical interface is enabled? (Choose two.)
Specify outgoing interface routing cost.
Configure SD-WAN rules interface preference.
Select SD-WAN balancing strategy.
Specify incoming interfaces in SD-WAN rules
Based on the exhibit, which statement about FortiGate re-evaluating traffic is true?
The type of traffic defined and allowed on firewall policy ID 1 is UDP.
Changes have been made on firewall policy ID 1 on FortiGate.
Firewall policy ID 1 has source NAT disabled.
FortiGate has terminated the session after a change on policy ID 1.
What are two reasons why FortiGate would be unable to complete the zero-touch provisioning process?(Choose two.)
The FortiGate cloud key has not been added to the FortiGate cloud portal.
FortiDeploy has connected with FortiGate and provided the initial configuration to contact FortiManager
FortiGate has obtained a configuration from the platform template in FortiGate cloud.
A factory reset performed on FortiGate
The zero-touch provisioning process has completed internally, behind FortiGate
Which two statements reflect the benefits of implementing the ADVPN solution to replace conventional VPN topologies? (Choose two.)
It creates redundant tunnels between hub-and-spokes, in case failure takes place on the primary links.
It dynamically assigns cost and weight between the hub and the spokes, based on the physical distance.
It ensures that spoke-to-spoke traffic no longer needs to flow through the tunnels through the hub.
It provides direct connectivity between all sites by creating on-demand tunnels between spokes.
Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)
Which two statements about the debug output are correct? (Choose two.)
The debug output shows per-IP shaper values and real-time readings.
This traffic shaper drops traffic that exceeds the set limits.
Traffic being controlled by the traffic shaper is under 1 Kbps.
FortiGate provides statistics and reading based on historical traffic logs.
Static routes using port2 are active in the routing table.
FortiGate has not received three consecutive requests from the SLA server configured for port2.
Which two configuration tasks are required to use SD-WAN? (Choose two.)
Add one or more members to an SD-WAN zone.
Configure at least one firewall policy for SD-WAN traffic.
Specify the outgoing interface routing cost.
Specify the incoming interfaces in SD-WAN rules.
A FortiGate device has the following LDAP configuration:
The administrator executed the ‘dsquery’ command in the Windows LDAp server 10.0.1.10, and got the following output: >dsquery user –samid administrator “CN=Administrator, CN=Users, DC=trainingAD, DC=training, DC=lab” Based on the output, what FortiGate LDAP setting is configured incorrectly?
An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled the IKE real time debug: diagnose debug application ike-1 diagnose debug enable
In which order is each step and phase displayed in the debug output each time a new dialup user is connecting to the VPN?
Which the following events can trigger the election of a new primary unit in a HA cluster? (Choose two.)
Primary unit stops sending HA heartbeat keepalives
The FortiGuard license for the primary unit is updated
One of the monitored interfaces in the primary unit is disconnected
A secondary unit is removed from the HA cluster
An administrator has enabled HA session synchronization in a HA cluster with two members. Which flag is added to a primary unit’s session to indicate that it has been synchronized to the secondary unit?
Examine the output of the ‘get router info ospf interface’ command shown in the exhibit; then answer the question below. Which statements are true regarding the above output? (Choose two.)
The port4 interface is connected to the OSPF backbone area
The local FortiGate has been elected as the OSPF backup designated router.
There are at least 5 OSPF routers connected to the port4 network.
Two OSPF routers are down in the port4 network.
Examine the output of the 'diagnose debug rating' command shown in the exhibit; then answer the question below.Which statement are true regarding the output in the exhibit? (Choose two.)
There are three FortiGuard servers that are not responding to the queries sent by the FortiGate
The TZ value represents the delta between each FortiGuard server's time zone and the FortiGate's time zone
FortiGate will send the FortiGuard queries to the server with highest weight
A server's round trip delay (RTT) is not used to calculate its weight.
An administrator cannot connect to the GIU of a FortiGate unit with the IP address 10.0.1.254. The administrator runs the debug flow while attempting the connection using HTTP. The output of the debug flow is shown in the exhibit: Based on the error displayed by the debug flow, which are valid reasons for this problem? (Choose two.)
HTTP administrative access is disabled in the FortiGate interface with the IP address 10.0.1.254.
Redirection of HTTP to HTTPS administrative access is disabled.
HTTP administrative access is configured with a port number different than 80.
The packet is denied because of reverse path forwarding check.
A FortiGate is rebooting unexpectedly without any apparent reason. What troubleshooting tools could an administrator use to get more information about the problem? (Choose two.)
Examine the output of the ‘diagnose ips anomaly list’ command shown in the exhibit; then answer the question below. Which IP addresses are included in the output of this command?
Those whose traffic matches a DoS policy.
Those whose traffic matches an IPS sensor
Those whose traffic exceeded a threshold of a matching DoS policy
Those whose traffic was detected as an anomaly by an IPS sensor.
Examine the following partial output from a sniffer command; then answer the question below.What is the meaning of the packets dropped counter at the end of the sniffer?
Number of packets that didn’t match the sniffer filter
Number of total packets dropped by the FortiGate
Number of packets that matched the sniffer filter and were dropped by the FortiGate.
Number of packets that matched the sniffer filter but could not be captured by the sniffer.
Which of the following statements are true about FortiManager when it is deployed as a local FDS? (Choose two.)
Caches available firmware updates for unmanaged devices..
Can be configured as an update server, or a rating server, but not both
Supports rating requests from both managed and unmanaged devices
Provides VM license validation services.
Which statement is true regarding File description (FD) conserve mode?
IPS inspection is affected when FortiGate enters FD conserve mode.
A FortiGate enters FD conserve mode when the amount of available, description is less than 5%.
FD conserve mode affects all daemons running on the device.
Restarting the WAD process is required to leave FD conserve mode.
A FortiGate's portl is connected to a private network. Its port2 is connected to the Internet. Explicit web proxy is enabled in port1 and only explicit web proxy users can access the Internet. Web cache is NOT enabled. An internal web proxy user is downloading a file from the Internet via HTTP. Which statements are true regarding the two entries in the FortiGate session table related with this traffic? (Choose two.)
Both session have the local flag on.
The destination IP addresses of both sessions are IP addresses assigned to FortiGate's interfaces.
One session has the proxy flag on, the other one does not.
One of the sessions has the IP address of port2 as the source IP address.
Four FortiGate devices configured for OSPF connected to the same broadcast domain. The first unit is elected as the designated router The second unit is elected as the backup designated router Under normal operation, how many OSPF full adjacencies are formed to each of the other two units?
What configuration changes can reduce the memory utilization in a FortiGate? (Choose two.)
Reduce the session time to live.
Increase the TCP session timers.
Increase the FortiGuard cache time to live.
Reduce the maximum file size to inspect.
View the exhibit, which contains the output of a debug command, and then answer thequestion below. Which of the following statements about the exhibit are true? (Choose two.)
The local FortiGate´s OSPF router ID is 0.0.0.4
FortiGate uses the Issued To: field in the server´s certificate.
FortiGate uses the requested URL from the user´s web browser.
View the exhibit, which contains the output of a BGP debug command, and then answer the question below. Which of the following statements about the exhibit are true? (Choose two.)
The FortiGuard web filter cache is disabled in the FortiGate´s configuration.
View the exhibit, which contains a partial output of an IKE real-time debug, and then answer the question below. Based on the debug output, which phase-1 setting is enabled in the configuration of this VPN?
View the following FortiGate configuration. All traffic to the Internet currently egresses from port1. The exhibit shows partial session information for Internet traffic from a user on the internal network: If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user´s session?
FortiGate used 209.222.147.36 as the initial server to validate its contract.
Examine the IPsec configuration shown in the exhibit; then answer the question below. An administrator wants to monitor the VPN by enabling the IKE real time debug using these commands: diagnose vpn ike log-filter src-addr4 10.0.10.1 diagnose debug application ike -1 diagnose debug enable The VPN is currently up, there is no traffic crossing the tunnel and DPD packets are being interchanged between both IPsec gateways. However, the IKE real time debug does NOT show any output. Why isn´t there any output?
The log-filter setting is set incorrectly. The VPN´s traffic does not match this filter.
A FortiGate device has the following LDAP configuration. The administrator executed the "dsquery" command in the Windows LDAp server 10.0.1.10, and got the following output: >dsquery user ""samid administrator "CN=Administrator, CN=Users, DC=trainingAD, DC=training, DC=lab" Based on the output, what FortiGate LDAP setting is configured incorrectly?
A corporate network allows Internet Access to FSSO users only. The FSSO user student does not have Internet access after successfully logged into the Windows AD network. The output of the "diagnose debug authd fsso list" command does not show student as an active FSSO user. Other FSSO users can access the Internet without problems. What should the administrator check? (Choose two.)
The user student must not be listed in the CA´s ignore user list.
The student workstation´s IP subnet must be listed in the CA´s trusted list.
At least one of the student´s user groups must be allowed by a FortiGate firewall policy.
Examine the output of the "get router info bgp summary" command shown in the exhibit; then answer the question below. Which statements are true regarding the output in the exhibit? (Choose two.)
A FortiGate is configured as an explicit web proxy. Clients using this web proxy are reposting DNS errors when accessing any website. The administrator executes the following debug commands and observes that the n-dns-timeout counter is increasing: What should the administrator check to fix the problem? (Choose Two.)
Examine the output of the "diagnose sys session list expectation" command shown in the exhibit; than answer the question below. Which statement is true regarding the session in the exhibit?
An administrator has configured a FortiGate device with two VDOMs: root and internal. The administrator has also created and inter-VDOM link that connects both VDOMs. The objective is to have each VDOM advertise some routes to the other VDOM via OSPF through the inter-VDOM link. What OSPF configuration settings must match in both VDOMs to have the OSPF adjacency successfully forming? (Choose three.)
An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled the IKE real time debug: diagnose debug application ike-1 diagnose debug enable In which order is each step and phase displayed in the debug output each time a new dial-up user is connecting to the VPN?
Examine the output of the "get router info ospf neighbor" command shown in the exhibit; then answer the question below. Which statements are true regarding the output in the exhibit? (Choose two.)
A FortiGate has two default routes: All Internet traffic is currently using port1. The exhibit shows partial information for one sample session of Internet traffic from an internal user: What would happen with the traffic matching the above session if the priority on the first default route (IDd1) were changed from 5 to 20?
Examine the following partial outputs from two routing debug commands; then answer the question below: Why the default route using port2 is not displayed in the output of the second command?
It is disabled in the FortiGate configuration.
The administrator does not have access to the remote gateway. Based on the debug output, which configuration change can the administrator make to the local gateway to resolve the phase 1 negotiation error?
Refer to the exhibits, which show the configuration on FortiGate and partial session information for internet traffic from a user on the internal network. If the priority on route ID 2 were changed from 10 to 0, what would happen to traffic matching that user session?
Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network An administrator would like to test session failover between the two service provider connections. What changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)
Refer to the exhibit, which contains a partial web filter profile configuration. Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?
The slave configuration is synchronized with the master.
port7 is used as the HA heartbeat on all devices in the cluster.
Master is selected based on the priority configured under config system ha.
The HA management IP is 169.254.0.2.
Examine the output from the BGP real time debug shown in the exhibit, then the answer the question below: Which statements are true regarding the output in the exhibit? (Choose two.)
Which two protocols in the IPsec suite are most used for authentication and encryption? (Choose two.)
Encapsulating Security Payload (ESP)
Secure Shell (SSH)
Internet Key Exchange (IKE)
Security Association (SA)
Which two settings can you configure to speed up routing convergence in BGP? (Choose two.)
update-source
set-route-tag
holdtime-timer
link-down-failover
Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the routing table, and the member status. The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule. Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?
The traffic will be load balanced across all three overlays.
The traffic will be routed over T_INET_0_0.
The traffic will be routed over T_MPLS_0.
The traffic will be routed over T_INET_1_0.
View the exhibit, which contains the partial output of an IKE real-time debug, and then answer the question below. ike 0: comes 10.0.0.2:500->10.0.0.1:500, ifindex=7.... ike 0: IKEv1 exchange=Aggressive id=baf47d0988e9237f/2f405ef3952f6fda len=430 ike 0: in BAF47D0988E9237F2F405EF3952F6FDA0110040000000000000001AE0400003C0000000100000001000000300101000 ike 0:RemoteSite:4: initiator: aggressive mode get 1st response... ike 0:RemoteSite:4: VID RFC 3947 4A131c81070358455C5728F20E95452F ike 0:RemoteSite:4: VID DPD AFCAD71368A1F1C96B8696FC77570100 ike 0:RemoteSite:4: VID FORTIGATE 8299031757A36082C6A621DE000502D7 ike 0:RemoteSite:4: peer is FortiGate/Fortios (v5 b727) ike 0:RemoteSite:4: VID FRAGMENTATION 4048B7D56EBCE88525E7DE7F00D6C2D3 ike 0:RemoteSite:4: VID FRAGMENTATION 4048B7D56EBCE88525E7DE7F00D6C2D3C0000000 ike 0:RemoteSite:4: received peer identifier FQDN "˜remore"™ ike 0:RemoteSite:4: negotiation result ike 0:RemoteSite:4: proposal id = 1: ike 0:RemoteSite:4: protocol id = ISAKMP: ike 0:RemoteSite:4: trans_id = KEY_IKE. ike 0:RemoteSite:4: encapsulation = IKE/none ike 0:RemoteSite:4: type=OAKLEY_ENCRYPT_ALG, val=AES_CBC, key ""len=128 ike 0:RemoteSite:4: type=OAKLEY_HASH_ALG, val=SHA. ike 0:RemoteSite:4: type-AUTH_METHOD, val=PRESHARED_KEY. ike 0:RemoteSite:4: type=OAKLEY_GROUP, val=MODP1024. ike 0:RemoteSite:4: ISAKMP SA lifetime=86400 ike 0:RemoteSite:4: ISAKMP SA baf47d0988e9237f/2f405ef3952f6fda key 16: B25B6C9384D8BDB24E3DA3DC90CF5E73 ike 0:RemoteSite:4: PSK authentication succeeded ike 0:RemoteSite:4: authentication OK ike 0:RemoteSite:4: add INITIAL-CONTACT ike 0:RemoteSite:4: enc BAF47D0988E9237F405EF3952F6FDA081004010000000000000080140000181F2E48BFD8E9D603F ike 0:RemoteSite:4: out BAF47D0988E9237F405EF3952F6FDA08100401000000000000008C2E3FC9BA061816A396F009A12 ike 0:RemoteSite:4: sent IKE msg (agg_i2send): 10.0.0.1:500-10.0.0.2:500, len=140, id=baf47d0988e9237f/2 ike 0:RemoteSite:4: established IKE SA baf47d0988e9237f/2f405ef3952f6fda
Which statements about this debug output are correct? (Choose two.)
The remote gateway IP address is 10.0.0.1.
It shows a phase 1 negotiation.
The negotiation is using AES128 encryption with CBC hash.
The initiator has provided remote as its IPsec peer ID.
Which three protocols are available only on the command line to configure as performance SLA status check? (Choose three.)
smtp
tcp-echo
twamp
udp-echo
icmp
What are two reasons why it is effective to implement the internet service database (ISDB) in an SD-WAN rule? (Choose two)
The ISDB is dynamically updated and reduces administrative overhead.
The ISDB applies rules to traffic from specific sources, based on application type.
The ISDB requires application control to maintain signatures and perform load-balancing.
The ISDB contains the IP addresses and port ranges of well-known destinations.
Refer to the exhibit. Based on the exhibit, which two actions does FortiGate perform on traffic passing through the SD-WAN member port2? (Choose two.)
FortiGate performs routing lookups for new sessions only after a route change.
FortiGate marks the routing information on existing sessions as persistent.
FortiGate flushes all routing information from the session table after a route change.
FortiGate always blocks all traffic after a route change.
Refer to the exhibits. ExhibitA shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate. Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?
port2 is referenced in a static route.
port1 is assigned a manual IP address.
port1 and port2 are not administratively down.
port1 is referenced in a firewall policy.
Refer to exhibits. Exhibit A shows the firewall policy and exhibit B shows the traffic shaping policy. The traffic shaping policy is being applied to all outbound traffic; however, inbound traffic is not being evaluated by the shaping policy. Based on the exhibits, what configuration change must be made in which policy so that traffic shaping can be applied to inbound traffic?
Create a new firewall policy, and the select the SD-WAN zone as Incoming Interface.
In the traffic shaping policy, select Assign Shaping Class ID as Action.
In the firewall policy, select Proxy-based as Inspection Mode.
In the traffic shaping policy, enable Reverse shaper, and then select the traffic shaper to use.
Refer to the exhibit, which shows the output of get system ha status. NGFW-1 and NGFW-2 have been up for a week. Which two statements about the output are true? (Choose two.)
If FGVM...649 is rebooted, FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster.
If no action is taken, the primary FortiGate will leave the cluster due to the current sync status.
If port7 becomes disconnected on the secondary, both FortiGate devices will elect itself the primary.
If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.
The slave configuration is not synchronized with the master.
The HA management IP is 169.254.0.2.
Master is selected because it is the only device in the cluster.
port 7 is used the HA heartbeat on all devices in the cluster.
